The most dangerous thing about Cloudflare’s new CMS isn’t a broken feature or missing plugin. It’s that you can wake up to a $13,000 bill with no built-in kill switch. That’s the counterintuitive truth about EmDash 0.1.0. Every page view, admin click, and API call hits Cloudflare Workers’ per-request pricing. There’s no spending cap. And unlike WordPress hosting’s flat $20/month, this serverless model charges you for every millisecond of CPU time and every database read.
Early testers are discovering bugs — authentication failures, content loss, broken previews — but those are fixable. The billing model is architectural. It’s the feature, not a bug. And it’s the one thing most coverage misses.
The billing model is architectural. It’s the feature, not a bug.
What’s Actually Broken in EmDash 0.1.0
Let’s be specific. This is a version 0.1.0 beta — 89 commits on GitHub, built in about two months with heavy AI assistance. Bugs are expected. But some are showstoppers for production use.
- Passkey authentication fails on Linux. The magic-link fallback returns a 404 page not found error. If you’re running a Linux dev environment, you may not be able to log in at all.
- Multi-tab editing loses content. One tester found that opening the same page in two tabs causes one to reset the other’s changes. For a CMS, losing a writer’s work is unforgivable.
- Front-end preview is not live. Changes saved in the editor don’t appear in preview without a manual refresh. Draft preview works, but not real-time.
- Custom content types are stored in the database, not code. You can create new content types from the admin UI, but there’s no way to define them in Astro config or deploy them as code. That’s a regression from modern headless CMS patterns where schema is version-controlled.
- The WordPress import tool is basic. It migrates posts, pages, and media, but not plugins, themes, custom blocks, or WooCommerce data. If you have a complex site, you’re rebuilding from scratch.
These are real problems. But they’re also the kind of problems a young project can fix in weeks. The billing problem is different.
The $13,000 Bill: How Serverless Pricing Can Backfire
Here’s the math that matters. EmDash on Cloudflare’s paid plan starts at $5/month and includes 10 million Worker requests. After that, you pay $0.30 per additional million requests plus CPU time. D1 database reads are billed per row. R2 storage charges per operation. KV lookups add up.
One page view can trigger four or five separate billing meters. A DDoS attack from 10,000 IPs, each making one request per second, racks up 26 billable requests in a month — and that’s just the start. Cloudflare offers no global spending cap. You can set CPU time limits per request and configure WAF rate limiting, but those don’t cap total requests. A distributed bot attack goes right through them.
A forum user calculated the scenario: 10,000 APIs × 1 req/sec × 30 days = 26 billion requests. At $0.30 per million after the free tier, that’s $7,800 just in Worker requests, plus database and storage charges. Total: $13,000 or more.
WordPress hosting charges a flat fee. Your server might crash under load, but your bill stays the same. EmDash flips that. The CMS keeps running perfectly under attack — and your credit card keeps getting charged.
The Plugin Sandbox: Great Idea, But Paid Only
EmDash’s headline feature is the plugin sandbox — every plugin runs in its own V8 isolate, with declared capabilities. A plugin that declares read contentcodecodecode and send emailcodecodecode literally cannot do anything else. No database access, no file system, no network calls unless granted. That’s a genuine architectural improvement over WordPress, where every plugin has full access to everything.
But here’s the catch. The sandbox requires Cloudflare’s dynamic workers, which are only available on the paid Workers plan ($5/month). On the free tier, plugins run in-process — no isolation, no sandbox. If you self-host EmDash on a regular Node.js server, there’s no sandbox support at all. The feature that justifies EmDash’s existence is locked behind Cloudflare’s proprietary runtime.
Cloudflare says the code is MIT licensed and you can run it anywhere. But the security model is not portable. That’s not lock-in by license — it’s lock-in by runtime.
The Ecosystem Void: Zero Plugins, Zero Themes, Zero Community
WordPress has 60,000+ plugins, 10,000+ themes, and millions of developers. EmDash 0.1.0 has zero third-party plugins. The built-in form plugin is rudimentary — “reminiscent of forms back in 2002,” as one tester put it. There’s no SEO plugin, no page builder, no e-commerce, no membership system.
Cloudflare’s counter-strategy is AI: every EmDash instance ships with an MCP server and agent skills files, so AI coding tools can generate plugins and themes programmatically. That’s a clever approach, but it assumes the user is comfortable with TypeScript and CLI tools. For the average WordPress site owner managing 12–15 plugins, that’s a non-starter.
History is brutal. Ghost launched over a decade ago with better technology than WordPress. It has 0.1% market share. Craft CMS, Statamic — technically excellent, ecosystem-starved. EmDash is starting from zero.
The Second-Order Effect Most Coverage Misses
Every article compares EmDash to WordPress on security and cost. But the deeper implication is this: EmDash shifts the economic risk of running a CMS from the hosting provider to the site owner.
With WordPress, you pay a predictable monthly fee. If you get hacked, the host may help restore your site. With EmDash, you pay per request. If you get attacked, you pay more. The platform has no incentive to stop the attack — it keeps serving requests and billing you. The only way to prevent runaway costs is to monitor Cloudflare dashboards daily and configure WAF rules yourself. That’s work most small publishers and bloggers don’t have time for.
WordPress’s flat-rate model is a feature, not a bug. It’s predictable. EmDash’s serverless model is cheaper at low traffic, but unpredictable at scale. For a business that can’t absorb a surprise $13,000 charge, that’s a dealbreaker.
Who Should Actually Use EmDash Right Now?
Honestly? Almost nobody in production.
If you’re a developer experimenting with TypeScript and Astro, spin up the playground. It’s free for an hour. Try the admin UI, test the block editor, see how portable text works. But don’t put a client’s site on it.
If you’re a small business owner or blogger, stick with WordPress. Keep your plugins updated, run backups, use a decent host, and run a security scanner. Those four things eliminate the practical risk EmDash is designed to solve — without the billing uncertainty.
If you’re an agency, EmDash has no agency tooling, no white-label options, no client portal, no staging workflow. WordPress offers all of that today.
Cloudflare could build a real ecosystem in 12–18 months. They could add spending caps, improve the import tool, and grow a plugin marketplace. But right now, EmDash is a proof of concept with a dangerous pricing model.
The bugs will be fixed. The billing model won’t.
- What is the most dangerous thing about EmDash 0.1.0?The most dangerous thing is the serverless billing model, which can result in a $13,000 bill with no built-in spending cap.
- What bugs does EmDash 0.1.0 have?Bugs include passkey authentication failure on Linux, multi-tab editing losing content, and a basic WordPress import tool.
- Who should use EmDash 0.1.0 right now?Almost nobody in production. Developers can experiment, but small businesses and agencies should stick with WordPress.